{"id":"CVE-2026-21440","summary":"AdonisJS Path Traversal in Multipart File Handling","details":"AdonisJS is a TypeScript-first web framework. A Path Traversal vulnerability in AdonisJS multipart file handling may allow a remote attacker to write arbitrary files to arbitrary locations on the server filesystem. This impacts @adonisjs/bodyparser through version 10.1.1 and 11.x prerelease versions prior to 11.0.0-next.6. This issue has been patched in @adonisjs/bodyparser versions 10.1.2 and 11.0.0-next.6.","aliases":["GHSA-gvq6-hvvp-h34h"],"modified":"2026-08-12T03:51:37.822118131Z","published":"2026-01-02T19:02:18.393Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-22"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/21xxx/CVE-2026-21440.json"},"references":[{"type":"WEB","url":"https://github.com/adonisjs/bodyparser/releases/tag/v10.1.2"},{"type":"WEB","url":"https://github.com/adonisjs/bodyparser/releases/tag/v11.0.0-next.6"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/21xxx/CVE-2026-21440.json"},{"type":"ADVISORY","url":"https://github.com/adonisjs/core/security/advisories/GHSA-gvq6-hvvp-h34h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-21440"},{"type":"FIX","url":"https://github.com/adonisjs/bodyparser/commit/143a16f35602be8561215611582211dec280cae6"},{"type":"FIX","url":"https://github.com/adonisjs/bodyparser/commit/6795c0e3fa824ae275bbd992aae60609e96f0f03"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/adonisjs/bodyparser","events":[{"introduced":"0"},{"fixed":"7728685025fc200d86ba46c1f5510198e4d3e9d2"},{"introduced":"0f61367f643a4d13248d00191fc45c8e075f11cb"},{"fixed":"63a672da7aa4c83dab770a9a11ced1df70ce7128"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0"},{"fixed":"10.1.2"},{"introduced":"11.0.0-next.0"},{"fixed":"11.0.0-next.6"}]}}],"versions":["v10.1.1","v11.0.0-next.5","v11.0.0-next.4","v11.0.0-next.3","v11.0.0-next.2","v11.0.0-next.1","v11.0.0-next.0","v10.1.0","v10.0.3","v10.0.2","v10.0.1","v10.0.0","v8.1.9","v8.1.8","v8.1.7","v8.1.6","v8.1.5","v8.1.4","v8.1.3","v8.1.2","v8.1.1","v8.1.0","v8.0.2","v8.0.1","v8.0.0","v7.1.5","v7.1.4","v7.1.3","v7.1.2","v7.1.1","v7.1.0","v7.0.1","v7.0.0","v6.0.0","v5.1.0","v5.0.8","v5.0.7","v5.0.6","v5.0.5","v5.0.4","v5.0.3","v5.0.2","v5.0.1","v5.0.0","v4.0.6","v4.0.5","v4.0.4","v4.0.3","v4.0.2","v4.0.1","v4.0.0","v3.2.7","v3.2.6","v3.2.5","v3.2.4","v3.2.3","v3.2.2","v3.2.1","v3.2.0","v3.1.0","v3.0.16","v3.0.15","v3.0.14","v3.0.13","v3.0.12","v3.0.11","v3.0.10","v3.0.9","v3.0.8","v3.0.7","v3.0.6","v3.0.5","v3.0.4","v3.0.3","v3.0.2","v3.0.1","v3.0.0","v2.0.9","v2.0.8","v2.0.7","v2.0.6","2.0.5","v2.0.4","v2.0.1","v2.0.0","v1.0.8","v1.0.7","v1.0.6","v1.0.5","v1.0.4","v1.0.3","v1.0.2","v1.0.1","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-21440.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}